Web Application Security
FortiWeb: Web Application Firewall (WAF) & API Protection
Machine Learning Enabled Protection for Business-Critical Applications
What is a Web Application Firewall?
FortiWeb, Fortinet’s Web Application Firewall, protects your business-critical web applications from attacks that target known and unknown vulnerabilities.
The attack surface of your web applications evolves rapidly, changing every time you deploy new features, update existing ones, or expose new web APIs. You need a solution that can keep up. FortiWeb is that solution.
FortiWeb’s WAF Solution
FortiWeb WAFs provide advanced features that defend your web applications and APIs from known and zero-day threats. Using an advanced multi-layered approach, FortiWeb protects against the OWASP Top 10 and more. FortiWeb ML customizes the protection of each application, providing robust protection without requiring the time-consuming manual tuning required by other solutions. With ML, FortiWeb identifies anomalous behavior and, more importantly, distinguishes between malicious and benign anomalies. The solution also features robust bot mitigation capabilities, allowing benign bots to connect (e.g. search engines) while blocking malicious bot activity.
FortiWeb offers deployment options that can protect business applications, no matter where the application is hosted. Options include hardware appliances, virtual machines, and containers that can be deployed in the data center, in cloud environments, or in the cloud-native SaaS solution, FortiWeb Cloud WAF as a Service.
Features and Benefits
Server and OS
FortiWeb protects against all OWASP Top-10 threats, DDoS attacks, malicious bot attacks, and more to defend mission-critical web applications and APIs.
Advanced Visual Analytics
FortiWeb’s visual reporting tools provide detailed analyses of attack sources, types and other elements that provide insights not available with other WAF solutions
ML-based Threat Detection
In addition to regular signature updates and many other layers of defenses, FortiWeb uses ML to protect against zero-day attacks and minimize false positives.
False Positive Mitigation Tools
Advanced tools that minimize the day-to-day management of policies and exception lists to ensure only unwanted traffic is blocked
Security Fabric Integration
Integration with FortiGate firewalls and FortiSandbox deliver protection from advanced persistent threats
Hardware-based Acceleration
FortiWeb delivers industry-leading protected WAF throughputs and blazing fast secure traffic encryption/decryption